Muse Front Door — docs

frontdoor-update-poll.cron.md

Poll the front-door distribution endpoint for repo updates and apply them. This is the consume side of the front-door update channel: the source repo publishes versioned tarballs to https://dist.muse-dev.online, and every provisioned machine polls that endpoint and converges on its own.

Install one of these on EVERY provisioned machine (including the source machine — there the poll is a harmless no-op while local is ahead of published). The runtime-side cron survives container rebuilds; VM-local processes don't.

Job body

Each run, via exec:

  1. Run:

REPO_TARBALL_URL=https://dist.muse-dev.online/muse-frontdoor.tar.gz ~/workspace/bin/update.sh >> ~/workspace/tunnel/frontdoor-update.log 2>&1 (If this machine's repo lives somewhere else, set FRONTDOOR_REPO too — update.sh honors it. The live ~/workspace/bin/update.sh is the stable entry point: it pulls the new repo, then deploys repo → live bin.) 2. update.sh is built for unattended runs: - Version-guarded: it reads the published VERSION first and exits quietly when local is already current — no download, no churn. - Never downgrades: a published version older than local is ignored. - Never clobbers work: if the repo has uncommitted changes, the run skips with a log line instead of overwriting them. - Every script is syntax-checked BEFORE anything is deployed; on failure the live system is untouched. - Live bin/ is timestamp-backed-up before deploy. - Only supervisors that are ALREADY RUNNING are restarted, and only if their script actually changed. Retired supervisors stay stopped. - The tunnel ssh process itself is never touched — updates cause zero tunnel downtime. 3. Stay silent when the log tail says already up to date, could not read published VERSION, or uncommitted changes — skipping. Those are the steady state, not news. 4. Report only: an applied update (update available: vX -> vY followed by now at version vY), or a genuine failure (download / syntax / deploy error — include the error text). A failure never leaves a half-deployed bin/: the script aborts before deploying.

Suggested cadence: every 6 hours. Convergence within a day is plenty for infra scripts; more frequent polling just burns egress.

Notes

~/memory/YYYY-MM-DD.md. - Never log secrets. The repo ships no secrets by construction (publish.sh builds from git archive of committed files only). - If a machine should stop tracking the channel (decommissioned, forked), disable this job there — do not just let it fail.